Executive brief
YARA is a pattern matching engine widely used by security teams to detect malware and analyze files. A vulnerability in how YARA reads compiled rule files (.yrc) allows an attacker to craft a malicious file that causes the application to crash or potentially execute arbitrary code through memory corruption. An attacker who can provide a .yrc file to a system running YARA can trigger a denial of service or memory corruption attack.
Technical details
An invalid pointer release vulnerability (CWE-763) exists in YARA 4.5.8's .yrc file deserializer, where external-variable pointers are not validated during load time. Unpatched pointer fields in the external-variable table can be set to arbitrary values by a crafted .yrc file, leading to invalid free in yr_rules_destroy() or wild-pointer dereference in yr_object_create() when the rules are used. The vulnerability is reachable via the public API (yr_rules_load_stream) and the command-line interface.
Affected products
- VirusTotal YARA 4.5.8
Timeline
- 2026-08-07: disclosed: Vulnerability reported on GitHub issue #2239
- 2026-09-22: advisory: CVE-2026-88340 published
- 2026-08-25: patched: Fix proposed in pull request #2244